Live data from Hacker News

I Am Releasing Ten Million Passwords

xato.net

201–210 of 229 posts

Re: I Am Releasing Ten Million Passwords

#202

Earlier quoted context omitted.

"threats may not be punished if a reasonable person would understand them as obvious hyperbole". Obviously, I don't know what the court would have held in this case, but it seems possible it would have held that this was "obvious hyperbole".

Could someone with legal background please explain the concept of "protected speech"? I thought the Constitution is "where the buck stops", the Supreme Law. It takes precedent over any law, legal theory, precedent, tradition, etc. The first amendment, as written, outright "enjoins" Congress from creating any "exceptions" or define what kinds of speech are actually protected. I also think the Constitution provides one…

Here's some details on the first amendment and what is and isnt protected under the constitution:

http://debmcalister.com/2011/06/03/7-things-you-cant-claim-f...

Some things not protected:

1 - Hate speech

2 - Speech that incites violence or encourages the audience to commit illegal or dangerous acts.

3 - “Material support“ to domestic or foreign terrorist groups,

4 - Public speech made in the conduct of their duties by public employees.

5 - Slander, libel or defamation.

6 - Publishing confidential, trade secret, or copyright material

7 - True threats. Like many other areas of First Amendment protection, context, target, and intent matter in determining what is or is not a true threat. Some threats are always illegal — any threat to the President of the U.S., for example.

While the constitution is broad in its definition of what is free speech, local, state and the federal government still have some say in what they considered to be covered by the first amendment. Even in some cases it's arbitrary such as the Westboro Baptist Church hateful protests are legal, while a kid burning a cross is not.

Re: I Am Releasing Ten Million Passwords

#203

It seems very useful for research and also practical uses, like how about a REST API with this dump? get will not only return true if it exists but how common and how weak it is, or will return a false for unique. Is there such a service out there?

With all due respect, I think this is a horrible idea. Isn't it just better to simply download the dump and filter the information with the command line? Why would someone even want to write a program that connects to an API to get info like this? You don't really need to know too much to be able to filter values like those, and it's way more flexible.

Re: I Am Releasing Ten Million Passwords

#205
Went ahead and performed a Levenshtein distance analysis from this list, and made a graph of it. Number 8 seems to be the sweet 'secure' spot that most people latch onto, though the distribution curve is interesting - or very human-like: http://pp19dd.com/2015/02/levenshtein-distance-10-million-us...

Re: I Am Releasing Ten Million Passwords

#206

Earlier quoted context omitted.

Could someone with legal background please explain the concept of "protected speech"? I thought the Constitution is "where the buck stops", the Supreme Law. It takes precedent over any law, legal theory, precedent, tradition, etc. The first amendment, as written, outright "enjoins" Congress from creating any "exceptions" or define what kinds of speech are actually protected. I also think the Constitution provides one…

Here's some details on the first amendment and what is and isnt protected under the constitution: http://debmcalister.com/2011/06/03/7-things-you-cant-claim-f... Some things not protected: 1 - Hate speech 2 - Speech that incites violence or encourages the audience to commit illegal or dangerous acts. 3 - “Material support“ to domestic or foreign terrorist groups, 4 - Public speech made in the conduct of their duties…

I disagree about the "hate speech" one. In particular, the article you link to cites Chaplinsky, which was limited very strongly by Brandenburg, Virginia v. Black, in which the court limited the statute in question to apply only when intimidation is intended, and Hustler v. Falwell, which the article gets completely backward - Hustler won!

Re: I Am Releasing Ten Million Passwords

#207

Earlier quoted context omitted.

In other words, supposing that this data is representative of most peoples' password practices, just trying these 20 passwords gives you a ~18% success rate for any username. And... dragon. That's an unusual password to make the top-10 list. I think this might be a somewhat skewed sampling.

It makes equally little sense to me, but "dragon" is routinely high on top password lists.

So is "jesus", and that doesn't seem to be true here. I find this list highly dubious, compared to others I've seen (and, long ago, obtained myself.)

Re: I Am Releasing Ten Million Passwords

#208
post #3

Barrett Brown was not convicted merely for linking to data on the web. He was convicted for three separate offenses: 1. Acting as a go-between for (presumably Jeremy Hammond) the Stratfor hacker and Stratfor itself, Brown misled Stratfor in order to throw the scent off Hammond. Having intimate knowledge of a crime doesn't make one automatically liable for that crime, but does put them in a precarious legal position i…

>The offense tied to Brown's "linking" was dismissed

This masks the scary reality that someone was indicted, arrested, and prosecuted for posting a link (not to mention that it was dismissed as part of a plea - not for lack of legal merit). While in this case there were other charges as well, there didn't have to be - all of the same pre-trial horrors (including possible detention without bail) could have occurred with only that charge. The fact that such a charge may eventually be dismissed/beaten at trial after your life is burnt to the ground for posting a link is little comfort.

Re: I Am Releasing Ten Million Passwords

#209

Earlier quoted context omitted.

"threats may not be punished if a reasonable person would understand them as obvious hyperbole". Obviously, I don't know what the court would have held in this case, but it seems possible it would have held that this was "obvious hyperbole".

Could someone with legal background please explain the concept of "protected speech"? I thought the Constitution is "where the buck stops", the Supreme Law. It takes precedent over any law, legal theory, precedent, tradition, etc. The first amendment, as written, outright "enjoins" Congress from creating any "exceptions" or define what kinds of speech are actually protected. I also think the Constitution provides one…

> It takes precedent over any law, legal theory, precedent, tradition, etc.

The framers were (mostly) lawyers, and wrote the document against the background of English common law: http://www.libertylawsite.org/liberty-forum/why-you-cant-und....

Exceptions to the "freedom of speech" are part of the Constitution, despite not being written in so many words, for the same reason "due process" requires a presumption of innocence, even though the latter phrase appears nowhere in the document.

Re: I Am Releasing Ten Million Passwords

#210
post #3

Barrett Brown was not convicted merely for linking to data on the web. He was convicted for three separate offenses: 1. Acting as a go-between for (presumably Jeremy Hammond) the Stratfor hacker and Stratfor itself, Brown misled Stratfor in order to throw the scent off Hammond. Having intimate knowledge of a crime doesn't make one automatically liable for that crime, but does put them in a precarious legal position i…

>The offense tied to Brown's "linking" was dismissed This masks the scary reality that someone was indicted, arrested, and prosecuted for posting a link (not to mention that it was dismissed as part of a plea - not for lack of legal merit). While in this case there were other charges as well, there didn't have to be - all of the same pre-trial horrors (including possible detention without bail) could have occurred wi…

That's also a misleading way of framing the issue. Brown wasn't charged with "criminal linking" (an offense that does not exist). He was charged with deliberately and knowingly assisting in the breach of Stratfor, and subsequent maximization of the damage from that breach. And remember, he was convicted of doing that; they just pursued a different vector for it than the link. Keep in mind also, they didn't just work back from people who posted links. Hector Monsegur ratted Brown out.

Most criminal statutes look insane if you ignore the mens rea component and consider only the actus reus.

Probably the right way to address your comment is to acknowledge the sentiment behind it. It would be ominous if prosecutors trawled the Internet looking for the wrong kinds of links --- people RT'ing updates from Anonymous, for instance, or relaying already-public newsworthy facts from breaches --- and fit accessory liability cases around those innocuous acts. It is worth being wary about prosecutors doing that, because computer crime laws are poorly rigged and set up terrible incentive systems for prosecutors.

It's just that those concerns are not yet vindicated by the Brown case.

Post reply on HN